Urgent.News

What's breaking now, across thousands of outlets.

Tech

Detectar vulnerabilidades en Go con gosec

En los laboratorios analizamos el código de una aplicación con SonarCloud, Snyk y Semgrep. En este ejercicio el punto de mira es el mismo código fuente, pero con una herramienta que no usamos en los labs: gosec , el analizador estático estándar del ecosistema de Go, que publica reglas mapeadas a CWE de la OWASP. Para demostrar que la herramienta funciona de verdad, la aplicamos a una aplicación…

Original Spanish Read in English

A group of engineers examined a piece of software using three different tools – SonarCloud, Snyk, and Semgrep. However, they decided to use gosec, a standard static analyzer in the Go ecosystem, which maps its rules to the Common Weakness Enumeration (CWE) standard of the Open Web Application Security Project (OWASP). They applied gosec to a deliberately flawed application written in Go. The tool found 17 issues, of which five were of high severity.

gosec scans the code for patterns that are known to be dangerous, such as storing credentials or private keys in the source code, using system commands with externally provided file paths, using weak hash algorithms, and constructing SQL queries by concatenating strings. Each rule has a unique identifier, a severity level, and an associated CWE. The results can be mapped to compliance requirements.

To run gosec, you need to install the Go compiler. If it's not installed, gosec will terminate without errors and report "Files: 0," giving the impression of a clean scan when it has not analyzed any code. The sample application is a small web server with six routes, each containing a deliberate flaw.

Five of the 17 findings are of high severity, while 11 are medium severity and one is low severity, making a total of 17 issues. The taint analysis rules (G702, G703, G705, and G710) provide more valuable insights than keyword-based rules. These rules follow the value of data as it flows through the function and identifies issues, such as executable commands constructed with user-provided data or insecure cryptographic primitives like MD5 and SHA1.

The authors emphasize that integration of gosec into automated pipelines is crucial. The "-no-fail" flag allows the scan to complete and display the full report, while "-severity = HIGH" failures can be triggered based on high-severity findings. A "#nosec G304" directive can be used to justify exceptions in the code. However, every #nosec should be carefully considered and justified in the code.

The tool can help detect false negatives, such as incorrect business logic without any known dangerous patterns, vulnerabilities in dependencies, and automatically generated code. However, it only supports Go, and a clean report does not guarantee the correctness of the code. It merely indicates that gosec did not find any issues. The difference between these two statements highlights the importance of relying on gosec for a comprehensive analysis rather than just relying on the absence of errors.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Rust's derive often implies inline

  • Rust #[derive] often adds #[inline] to core traits like Debug
  • Inlining Debug implementations can significantly increase binary size
  • Preventing inlining can reduce binary size by 160KB in some cases

The Task Ahead of STN as National Telecoms Licence Operator in Nigeria

After 28 years of operating skeletal telecoms services under the umbrella, Swift Telephone Network (STN) has become a full-fledged telecoms operator after being granted the Universal Access Service…

  • Swift Telephone Network (STN) secured UASL from NCC, enabling nationwide telecom services.
  • Post-2017 revival, Oluwole Adetuyi focused on regulatory compliance before receiving UASL in 2022.

MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication.

  • Four unauthenticated CVEs discovered in MCP servers
  • Vulnerabilities allow unauthorized access and code execution
  • Fixes available but not widely adopted

More from Sunday 4 October →